Skip to main content

Microsoft Releases May 2022 Security Updates

Scheduled updates for Microsoft products

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Scheduled updates for Microsoft products


The following platforms are also known to be affected:

Other products included

  • Windows Active Directory
  • Microsoft Graphics Component
  • Microsoft Local Security Authority Server (lsasrv)
  • Microsoft Office Excel
  • Microsoft Windows ALPC
  • Role: Windows Fax Service
  • Role: Windows Hyper-V
  • Self-hosted Integration Runtime
  • Tablet Windows User Interface
  • Visual Studio Code
  • Windows Active Directory
  • Windows Address Book
  • Windows Authentication Methods
  • Windows BitLocker
  • Windows Cluster Shared Volume (CSV)
  • Windows Failover Cluster Automation Server
  • Windows Kerberos
  • Windows Kernel
  • Windows LDAP - Lightweight Directory Access Protocol
  • Windows Media
  • Windows Network File System
  • Windows NTFS
  • Windows Point-to-Point Tunneling Protocol
  • Windows Print Spooler Components
  • Windows Push Notifications
  • Windows Remote Access Connection Manager
  • Windows Remote Desktop
  • Windows Remote Procedure Call Runtime
  • Windows Server Service
  • Windows Storage Spaces Controller
  • Windows WLAN Auto Config Service

Threat details

Introduction

Microsoft has released updates to address 75 vulnerabilities in Microsoft software, with 8 vulnerabilities considered critical. An unauthenticated remote attacker can exploit some of these vulnerabilities to take control of an affected system.

Exploitation of CVE-2022-26925 in the wild

On 1 July 2022, CISA added CVE-2022-26925, a 'Windows Local Security Authority (LSA) Spoofing Vulnerability', to their Known Exploited Vulnerabilities Catalog. This catalogue is used to describe vulnerabilities that are frequent attack vectors for malicious cyber actors and therefore pose a significant risk.

The vulnerability was addressed in the out-of-band (OOB) updates to Microsoft's May 2022 Security Update (see the Threat Updates section below).

CVE-2022-26925 could be exploited as part of a New Technology LAN Manager (NTLM) Relay Attack, which enables an attacker-controlled device to assume the identity and privileges of a targeted device. If a domain controller is targeted, this could result in a full domain compromise. 

Further details of this vulnerability, including advice for protecting against NTLM Relay Attacks, can be found on Microsoft's Security Update Guide for CVE-2022-26925.


Threat updates

Date Update
20 May 2022 Microsoft releases out-of-band update to address authentication failure issues after installing the May Windows update

Microsoft have released out-of-band (OOB) updates for Domain Controllers in response to the authentication failures observed after applying the May 2022 monthly security updates. These failures were related to how the mapping of certificates to machine accounts was being handled by the domain controller.  

Affected organisations are encouraged to review the relevant advisories below.

Cumulative updates

 

 

 

Standalone Updates:

 

 

 


Remediation advice

Affected organisations are encouraged to review Microsoft’s May 2022 Security Update Summary and Deployment Information and apply the necessary updates.



Last edited: 4 July 2022 1:27 pm